CVE-2026-17176

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 00:17

Updated : 2026-09-11 15:21


NVD link : CVE-2026-17176

Mitre link : CVE-2026-17176

CVE.ORG link : CVE-2026-17176


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')